A critical vulnerability in Drupal AlternativeCommerce (Basket) allows arbitrary PHP code execution. This affects versions prior to 2.1.17.